2019 CVE Vulnerabilities

17,621 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-10763MEDIUM6.5pimcore/pimcore before 6.3.0 is vulnerable to SQL Injection. An attacker with limited privileges (classes permission) ca...
CVE-2019-3424HIGH8.2authentication issues vulnerability, which exists in V2.1.14 and below versions of C520V21 smart camera devices. An atta...
CVE-2019-3423MEDIUM5.3permission and access control vulnerability, which exists in V2.1.14 and below versions of C520V21 smart camera devices....
CVE-2019-12311MEDIUM6.1Sandline Centraleyezer (On Premises) allows Unrestricted File Upload leading to Stored XSS. An HTML page running a scrip...
CVE-2019-12299MEDIUM6.1Sandline Centraleyezer (On Premises) allows Stored XSS using HTML entities in the name field of the Category section.
CVE-2019-12271CRITICAL9.8Sandline Centraleyezer (On Premises) allows unrestricted File Upload with a dangerous type, because the feature of addin...
CVE-2019-5688MEDIUM6.7NVIDIA NVFlash, NVUFlash Tool prior to v5.588.0 and GPUModeSwitch Tool prior to 2019-11, NVIDIA kernel mode driver (nvfl...
CVE-2019-5102MEDIUM5.9An exploitable information leak vulnerability exists in the ustream-ssl library of OpenWrt, versions 18.06.4 and 15.05.1...
CVE-2019-5101MEDIUM5.9An exploitable information leak vulnerability exists in the ustream-ssl library of OpenWrt, versions 18.06.4 and 15.05.1...
CVE-2019-19113CRITICAL9.8main/resources/mapper/NewBeeMallGoodsMapper.xml in newbee-mall (aka New Bee) before 2019-10-23 allows search?goodsCatego...
CVE-2019-10172HIGH7.5A flaw was found in org.codehaus.jackson:jackson-mapper-asl:1.9.x libraries. XML external entity vulnerabilities similar...
CVE-2019-19085MEDIUM5.4A persistent cross-site scripting (XSS) vulnerability in Octopus Server 3.4.0 through 2019.10.5 allows remote authentica...
CVE-2019-19084MEDIUM4.3In Octopus Deploy 3.3.0 through 2019.10.4, an authenticated user with PackagePush permission to upload packages could up...
CVE-2019-17058CRITICAL9.1Footy Tipping Software AFL Web Edition 2019 allows arbitrary file upload and resultant remote code execution because a w...
CVE-2019-17057MEDIUM6.1Footy Tipping Software AFL Web Edition 2019 allows XSS.
CVE-2019-14467HIGH7.8The Social Photo Gallery plugin 1.0 for WordPress allows Remote Code Execution by creating an album and attaching a mali...
CVE-2019-19083MEDIUM4.7Memory leaks in *clock_source_create() functions under drivers/gpu/drm/amd/display/dc in the Linux kernel before 5.3.8 a...
CVE-2019-19082MEDIUM4.7Memory leaks in *create_resource_pool() functions under drivers/gpu/drm/amd/display/dc in the Linux kernel through 5.3.1...
CVE-2019-19081MEDIUM5.9A memory leak in the nfp_flower_spawn_vnic_reprs() function in drivers/net/ethernet/netronome/nfp/flower/main.c in the L...
CVE-2019-19080MEDIUM5.9Four memory leaks in the nfp_flower_spawn_phy_reprs() function in drivers/net/ethernet/netronome/nfp/flower/main.c in th...
CVE-2019-19079HIGH7.5A memory leak in the qrtr_tun_write_iter() function in net/qrtr/tun.c in the Linux kernel before 5.3 allows attackers to...
CVE-2019-19078HIGH7.5A memory leak in the ath10k_usb_hif_tx_sg() function in drivers/net/wireless/ath/ath10k/usb.c in the Linux kernel throug...
CVE-2019-19077MEDIUM5.5A memory leak in the bnxt_re_create_srq() function in drivers/infiniband/hw/bnxt_re/ib_verbs.c in the Linux kernel throu...
CVE-2019-19076MEDIUM5.9A memory leak in the nfp_abm_u32_knode_replace() function in drivers/net/ethernet/netronome/nfp/abm/cls.c in the Linux k...
CVE-2019-19075HIGH7.5A memory leak in the ca8210_probe() function in drivers/net/ieee802154/ca8210.c in the Linux kernel before 5.3.8 allows ...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now